VMware Workstation 4.0 for Linux allows local users to overwrite arbitrary files and gain privileges via "symlink manipu
The Xsun server for Sun Solaris 2.6 through 9, when running in Direct Graphics Access (DGA) mode, allows local users to
Race condition in SSH Tectia Server 4.0.3 and 4.0.4 for Unix, when the password change plugin (ssh-passwd-plugin) is ena
Linux kernel 2.4.10 through 2.4.21-pre4 does not properly handle the O_DIRECT feature, which allows local attackers with
A patch for shadow-utils 20000902 causes the useradd command to create a mail spool files with read/write privileges of
mv in IRIX 6.5 creates a directory with world-writable permissions while moving a directory, which could allow local use
The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local user
dexconf in XFree86 Xserver 4.1.0-2 creates the /dev/dri directory with insecure permissions (666), which allows local us
Portmon 1.7 and possibly earlier versions allows local users to read and write arbitrary files via the (1) -c (host file
Mantis 0.17.5 and earlier stores its database password in cleartext in a world-readable configuration file, which allows
Directory traversal vulnerability in phpSysInfo 2.1 and earlier allows attackers with write access to a local directory
FDclone 2.00a, and other versions before 2.02a, creates temporary directories with predictable names and uses them if th
Integer overflow in the f_count counter in FreeBSD before 4.2 through 5.0 allows local users to cause a denial of servic
Untrusted search path vulnerability in Qualcomm qpopper 4.0 through 4.05 allows local users to execute arbitrary code by
Worker Filemanager 1.0 through 2.7 sets the permissions on the destination directory to world-readable and executable wh
Absolute path traversal vulnerability in Alt-N Technologies WebAdmin 2.0.0 through 2.0.2 allows remote attackers with ad
chpass in OpenBSD 2.0 through 3.2 allows local users to read portions of arbitrary files via a hard link attack on a tem
Openwebmail in cPanel 5.0, when run using suid Perl, adds the directory in the SCRIPT_FILENAME environment variable to P
Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to s
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters bet
Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencode
Multiple race conditions in the handling of O_DIRECT in Linux kernel prior to version 2.4.22 could cause stale data to b
Unknown vulnerability in Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to cause a denial of service
Buffer overflow in the Yahoo! Audio Conferencing (aka Voice Chat) ActiveX control before 1,0,0,45 allows remote attacker
Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send req
Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive informati
rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to
faxspool in mgetty before 1.1.29 uses a world-writable spool directory for outgoing faxes, which allows local users to m
Internet Message (IM) 141-18 and earlier uses predictable file and directory names, which allows local users to (1) obta
The data collection script for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 sets world-
The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause
The DEC UDK processing feature in the hanterm (hanterm-xf) terminal emulator before 2.0.5 allows attackers to cause a de
Unknown vulnerability in UFS for Solaris 9 for SPARC, with logging enabled, allows local users to cause a denial of serv
NetBSD 1.4 through 1.6 beta allows local users to cause a denial of service (kernel panic) via a series of calls to the
Symbolic link vulnerability in xbreaky before 0.5.5 allows local users to overwrite arbitrary files via a symlink from t
Web Server 4D (WS4D) 3.6 stores passwords in plaintext in the Ws4d.4DD file, which allows attackers to gain privileges.
ptrace on HP-UX 11.00 through 11.11 allows local users to cause a denial of service (data page fault panic) via "an inco
SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port
Memory leak in lofiadm in Solaris 8 allows local users to cause a denial of service (kernel memory consumption).
psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/bef
ps2epsi creates insecure temporary files when calling ghostscript, which allows local attackers to overwrite arbitrary f
BitchX IRC client 1.0c20cvs and earlier allows attackers to cause a denial of service (core dump) via certain channel mo
znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Unknown vulnerability in patches 108993-14 through 108993-19 and 108994-14 through 108994-19 for Solaris 8 may allow loc
Multiple vulnerabilities in noweb 2.9 and earlier creates temporary files insecurely, which allows local users to overwr
Integer signedness error in the Linux Socket Filter implementation (filter.c) in Linux 2.4.3-pre3 to 2.4.22-pre10 allows
The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the cal
The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/sel
/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow lo
GDM before 2.4.1.6, when using the "examine session errors" feature, allows local users to read arbitrary files via a sy
Scan for 2003 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started